Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 7 articles for you...
212

Enhancing Container Security Through Admission Control in Kubernetes

Kubernetes adoption is up - and so is the number of security incidents in container and Kubernetes environments. One of the ways that organizations can tackle this issue is by focusing on securing the container supply chain. . Kubernetes adoption is up, but many organizations are suffering security incidents in their container and Kubernetes environments. In the fall edition of the “State of Container and Kubernetes Security” report, for instance, 91% of respondents told StackRox that they had adopted the container orchestration platform. That’s about the same proportion (90%) of survey participants that admitted to having suffered a security incident in their Kubernetes and container environments over the preceding 12 months. Two-thirds of those security incidents consisted of a misconfiguration issue. Those events were followed by a vulnerability incident (22%), a runtime incident (17%) and a failed audit (16%). Nearly half (44%) of respondents said that they ultimately delayed moving an application into production as a result of their security concerns. . The utilization of cloud-native technologies is growing, yet security breaches within orchestrated systems persist in posing difficulties for enterprises.. Kubernetes Security, Container Incidents, Secure Supply Chain, Dynamic Admission Control. . Brittany Day

Calendar%202 May 13, 2021 User Avatar Brittany Day Cloud Security
83

Consequences Of The OPM Data Breach: 21.5 Million Individuals Impacted

Data breaches at the U.S. government's personnel management agency by hackers, with suspicions centering on China, involves millions more people than previously estimated, U.S. officials said on Thursday.. The Office of Personnel Management (OPM) said data stolen from its computer networks included Social Security numbers and other sensitive information on 21.5 million people who have undergone background checks for security clearances. The link for this article located at Reuters is no longer available. . The Office of Personnel Management (OPM) said data stolen from its computer networks included Social. breaches, government's, personnel, management, agency, hackers, suspicions, cente. . LinuxSecurity.com Team

Calendar%202 Jul 10, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

2014 Major Security Incidents: Heartbleed, Shellshock and Tor Growth

Epic hacks, major vulnerabilities, and other security surprises rolled across the Internet like a tidal wave in 2014. We thought we. Beyond major hacks and tragedies, there were also positive developments. Google and Yahoo got serious about email crypto, Android and iOS beefed up their encryption, and Tor won a major supporter. The link for this article located at Network World is no longer available. . 2014 reshaped the cybersecurity landscape with high-profile breaches like Heartbleed, prompting organizations to enhance data protection and encryption practices. 2014 Cybersecurity Incidents, Major Hacks Overview, Tor Security Advancements, Encryption Developments. . LinuxSecurity.com Team

Calendar%202 Dec 19, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
82

Coordinated Cyberattacks by FBI Informant on Several Nations

An informant working for the F.B.I. coordinated a 2012 campaign of hundreds of cyberattacks on foreign websites, including some operated by the governments of Iran, Syria, Brazil and Pakistan, according to documents and interviews with people involved in the attacks.. Exploiting a vulnerability in a popular web hosting software, the informant directed at least one hacker to extract vast amounts of data The link for this article located at NY Times is no longer available. . CIA asset orchestrated digital assaults against overseas governments, leveraging weaknesses in cloud infrastructure.. Cyberattack Campaigns, FBI Operatives, Web Hosting Exploits. . Alex

Calendar%202 Apr 24, 2014 User Avatar Alex Government
82

North Korean DDoS Attacks: March 2023 Examination and Future Risks

The cyber attacks that paralyzed a handful of major South Korean websites earlier this year were almost certainly carried out by North Korea or parties allied with the country, computer security company McAfee said Tuesday in a report.. The company's analysis, carried out with the help of the South Korean and U.S. governments, is one of the most thorough yet published on the March attacks, and details how they were carried out, and why they were so difficult to counter. In investigating the incident, the report draws clear parallels with a similar attack that knocked South Korean and U.S. websites offline in 2009 and comes to an unsettling conclusion: the attacks were likely designed to test South Korea's cyber defense and response, and could be the prelude of a much larger attack in the future. The link for this article located at Network World is no longer available. . The company's analysis, carried out with the help of the South Korean and U.S. governments, is one o. cyber, attacks, paralyzed, handful, major, south, korean, websites, earlier. . Alex

Calendar%202 Jul 06, 2011 User Avatar Alex Government
81

Evaluating Google's Cloud Storage Trust Amid Security Concerns

Google is pushing full steam ahead with their office strategy, and their hope is to convince a lot of individuals and businesses to trust Google enough to store their documents on Google's servers instead of their own computers, or servers under their control. The fact that unauthorized document access is a simple password guess or government "request" away already works against them. But the steady stream of minor security incidents we've seen (many very recently) can also hurt Google in the long run. Running applications for businesses is serious stuff, and Google needs to be diligent about security. . The link for this article located at TechCrunch is no longer available. . Google's security missteps can erode user trust, leading individuals and businesses to reconsider their cloud data storage options amid growing competition.. Google Security, Cloud Storage Risks, User Trust Issues, Data Privacy, Business Application Security. . LinuxSecurity.com Team

Calendar%202 Oct 19, 2006 User Avatar LinuxSecurity.com Team Privacy
83

Future Trends in Software Security: Addressing Risks and Optimism

There's no need to imagine a worst-case scenario for Internet security in the year 2010. The worst-case scenario is unfolding right now. Based on conservative projections, we'll discover about 100,000 new software vulnerabilities in 2010 alone, or one new bug every five minutes of every hour of every day. The number of security incidents worldwide will swell to about 400,000 a year, or 8,000 per workweek. . . .. Windows will approach 100 million lines of code, and the average PC, while it may cost $99, will contain nearly 200 million lines of code. And within that code, 2 million bugs. By 2010, we'll have added another half-a-billion users to the Internet. A few of them will be bad guys, and they'll be able to pick and choose which of those 2 million bugs they feel like exploiting. In other words, today's sloppiness will become tomorrow's chaos. The good news is that we probably won't get to that point. Most experts are optimistic about the future security of the Internet and software. Between now and 2010, they say, vulnerabilities will flatten or decline, and so will security breaches. They believe software applications will get simpler and smaller, or at least they won't bloat the way they do now. And they think experience will provide a better handle on keeping the growing number of bad guys out of our collective business. Some even suggest that by 2010, a software Martin Luther will appear to nail 95 Theses--perhaps in the form of a class-action lawsuit--to a door in Redmond, kicking off a full-blown security reformation. The link for this article located at ComputerWorld is no longer available. . Windows will approach 100 million lines of code, and the average PC, while it may cost $99, will con. there's, imagine, worst-case, scenario, internet, security, worst-c. . LinuxSecurity.com Team

Calendar%202 Dec 31, 2003 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

E-Commerce Growth Intertwined With Internet Fraud Trends

Internet use is still growing fast, but so is Internet-based fraud, according to security vendor VeriSign Inc., which examined data from its own infrastructure services between August 2002 and August 2003.. . .. Internet use is still growing fast, but so is Internet-based fraud, according to security vendor VeriSign Inc., which examined data from its own infrastructure services between August 2002 and August 2003. According to VeriSign's study "Internet Security Intelligence Briefing," released yesterday, 6.2% of e-commerce transactions carried out in the U.S. were attempts at fraud. More than half the fraud attempts were made by entities outside the U.S., VeriSign said. Also, the number of security incidents almost doubled between May and August this year, VeriSign said. Standard security attacks and fraud are closely linked, the company said. "Analysis ... showed extremely high correlation (47%) between sources of fraud and sources of security attacks," the study said. "Attackers who gain control of Internet host machines are using these compromised hosts for both security attacks and fraudulent e-commerce transactions." Other findings from the study include the following: Total DNS queries, such as those aimed at finding Web sites and e-mail addresses, grew by 51.4% between August 2002 and August 2003. E-mail-related DNS queries rose by 245% over the same period, partly because of the surge in spam and mass-mailing viruses such as Bugbear. The average number of Internet transactions per online merchant site has grown 17% in the past year. SSL has become the de facto e-commerce security standard at more than 400,000 sites, with growth of 6% in certificates issued over the past year. Security incidents per device rose 99% this year between May and August, with the Blaster worm contributing most of the increase in August. The trend in viruses and worms is toward more sophisticated, potent and coordinated attacks along the lines of Blaster, Nachi and Sobig.F, which was the first virus todirect itself at the Internet's root servers. Security incidents were principally generated in the U.S. (81%), but the percentage of fraud attempts made from the U.S. was much lower (48%). One reason for the difference is the weak policing of the Internet outside the U.S., according to VeriSign. "International criminals can essentially commit fraud with impunity, given that jurisdiction issues make policing international fraud near impossible," the report said. Following the U.S. in the fraud stakes was the U.K. (5.25%), while in third place was Nigeria (4.81%), where the 419, or advance-fee, fraud epidemic rages unchecked. All of article The link for this article located at ComputerWorld is no longer available. . Digital connectivity is on the rise, but so are scams. Uncover the relationship between cyber attacks and e-commerce activities.. E-commerce Growth, Fraud Attempts, Internet Security. . LinuxSecurity.com Team

Calendar%202 Oct 14, 2003 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200